SMS messages are not encrypted. Theoretically, this allows telecommunications providers to scan for and blacklist spam campaigns at the network level, if they make enough noise. On the other hand, messages sent via RCS or iMessage are encrypted end-to-end. Although an iMessage will route directly through an Apple server, Apple itself cannot read the content in transit. Lucid takes advantage of this by sending phishing texts via iMessage and RCS, turning this otherwise positive security feature on its head.
That's it. That's the "fault" that is being "exploited" that they mention multiple times in the lead-in to the article.